Defensibility check: the core statistics in this piece come from two vendor-sponsored surveys (OneTrust and Veeam) — both companies sell AI governance/backup tooling, so I’m attributing every number to its source explicitly rather than presenting vendor research as independently audited fact.
Two separate September 2026 surveys from two different vendors landed on the same uncomfortable number, independently, using different methodologies. That kind of convergence is worth paying attention to — even with the appropriate vendor-research caveat attached.
The numbers, and who’s reporting them
OneTrust’s second annual 2026 AI-Ready Governance Report — based on a survey of 1,200 senior business decisionmakers across eight countries, conducted by Sapio Research on OneTrust’s behalf — found:
- 87% of surveyed organizations encourage AI agent use, but only 47% have clear governance, oversight, and controls in place.
- 86% experienced at least one AI-related incident in the past year (sensitive data exposure, unapproved employee AI use, misinformation, or data loss).
- Only 27% slowed or paused AI deployment in response to those incidents — most instead just increased employee training (49%).
- 33% saw employees turn to unapproved AI tools because sanctioned tools or approval processes weren’t available fast enough — governance friction directly fueling shadow AI.
Separately, a Veeam-commissioned EMEA survey found three in four enterprises report no clear oversight of their AI agents — a distinct data point, from a distinct vendor, pointing at the same underlying gap.
Important context on both surveys: OneTrust sells an “AI-Ready Governance Platform,” and Veeam sells backup/data protection and increasingly governance-adjacent tooling. Both have a direct commercial interest in the market believing this gap is real and needs their product. That doesn’t make the numbers wrong — but it means these are vendor-sponsored findings, not independently audited research, and should be read that way.
Why the gap exists — and why it’s not a staffing problem
OneTrust’s Chief Innovation Officer Blake Brannon put it well in the report: “Every company is trying to hold on to two things at once: the speed they are getting from AI, and control over what AI does… That is a design problem, not a staffing problem.”
That distinction matters. The traditional governance model assumes you can define in advance what a system will do, then write rules to control it. AI agents break that assumption — the same underlying capability can be genuinely useful in one context and genuinely harmful in another, depending on what it’s asked to do and what data it touches. Static, pre-written rules don’t map cleanly onto that kind of variable, judgment-dependent behavior.
What this actually looks like inside a real organization
Having managed IT governance directly, the pattern OneTrust describes is recognizable, not abstract: someone in a department finds an AI tool that solves a real problem faster than the sanctioned option. IT hasn’t reviewed it yet — not out of negligence, but because review capacity hasn’t scaled with the number of tools showing up. The employee uses it anyway because the business need is real and immediate. Multiply that across a few hundred employees and dozens of AI tools, and you get exactly the pattern in the data: high adoption, thin oversight, and shadow usage filling the gap whenever official approval lags behind actual need.
The 33% shadow-AI figure is the most operationally important number in the whole report, arguably more than the headline 87/47 gap — it’s the direct, measurable consequence of governance being too slow relative to how fast people find and adopt new tools.
What organizations are actually doing about it
The data shows two things happening simultaneously: incident response staying weak (only 27% pause deployment after incidents) while investment intent is strong (98% plan to increase AI governance budgets next year, averaging a 25% increase, and 80% report already spending meaningfully more time on AI risk management than a year ago). That’s a company recognizing the problem is real and committing resources — while still not yet closing the actual gap in the day-to-day.
The bottom line
Two independent vendor surveys converge on the same finding: AI agent adoption is running well ahead of the governance infrastructure needed to actually oversee it, and that gap is directly fueling shadow AI use rather than closing on its own. The numbers come from companies with a commercial stake in the answer, so treat the specific percentages as vendor-reported, not independently audited — but the underlying pattern (fast adoption, slow governance, workarounds filling the gap) matches what’s observable directly inside organizations managing this problem in real time, and it’s not going away by ignoring it.
Sources: OneTrust, 2026 AI-Ready Governance Report, announced via press release (September 14, 2026; vendor-sponsored survey, methodology by Sapio Research); Compare the Cloud, independent coverage of Veeam’s EMEA enterprise AI oversight survey; NewsBreak, framing coverage on AI governance racing to keep up with adoption.